The crypto industry has long been plagued by hacking incidents and security breaches. However, the emergence of artificial intelligence (AI) is exacerbating this issue. Charles Guillemet, chief technology officer at Ledger, a prominent crypto wallet provider, asserts that AI-powered tools are making it faster and more affordable for hackers to launch attacks, thereby disrupting the economics of cybersecurity. "Identifying and exploiting vulnerabilities has become extremely easy," Guillemet stated in an interview.
"The cost of doing so is essentially zero." His comments come amidst a surge in high-profile crypto heists, including the recent $285 million exploit of Solana-based DeFi protocol Drift and the $25 million attack on yield protocol Resolv. According to DefiLlama, over $1.4 billion in assets were lost or stolen in crypto attacks over the past year. The traditional security paradigm, which relies on the notion that hacking a system should be more difficult and costly than the potential reward, is being eroded by AI. Tasks that previously required skilled researchers months to complete, such as reverse engineering software or chaining exploits, can now be accomplished in seconds with the right prompts.
For the crypto industry, where code often controls large pools of funds, this shift significantly raises the stakes. "You need to be perfect," Guillemet cautioned teams developing blockchain protocols.
The problem is further complicated by AI-generated code, which can spread vulnerabilities more rapidly as more developers rely on AI tools. "There is no 'make it secure' button," he emphasized. "We will produce a lot of code that will be insecure by design." To address this issue, crypto protocols must rethink security from the ground up. Guillemet advocated for formal verification, which involves using mathematical proofs to validate code, as a more robust approach than traditional audits.
He also highlighted hardware-based security, such as devices like hardware wallets that isolate private keys from internet-connected systems, reducing exposure. "When you have a dedicated device not exposed to the internet, it is more secure by design," he said. As malware becomes increasingly sophisticated, this approach is becoming more relevant. Guillemet described attacks that scan compromised phones for wallet seed phrases, allowing hackers to drain funds without user interaction.
For average crypto users, Guillemet's message is clear: assume that systems can and will fail. "You can't trust most of the systems you use," he said. This may lead more users to adopt cold storage, stronger operational security, and keeping sensitive data offline. However, even then, risks extend beyond software, including physical attacks targeting crypto holders.
Guillemet expects a divide ahead, with critical systems like wallets and protocols investing heavily in security and adapting, while much of the broader software ecosystem may struggle to keep up. "It's really easier to hack everything," he warned.